Topic: security

Rust establishes new security team

The Rust Foundation, the nonprofit organization for the Rust programming language, today announced that it will be establishing a dedicated security team, underwritten by the OpenSSF’s Alpha-Omega Initiative as well as the foundation’s newest platinum member, JFrog.  “There’s often a misperception that because Rust ensures memory safety that it’s one hundred percent secure, but Rust … continue reading

Sephora becomes the first company fined for violating CCPA

California Attorney General Rob Bonta has announced a settlement with the beauty brand Sephora over allegations that the company has violated California’s landmark privacy law, the California Consumer Privacy Act (CCPA). According to Bonta, it was determined after an enforcement sweep that Sephora failed to disclose to customers that the company was selling their personal … continue reading

A guide to API management tools

The following is a listing of API management tool providers, along with a brief description of their offerings.  Apigee is an API management platform for modernizing IT infrastructure, building microservices and managing applications. The platform was acquired by Google in 2016 and added to the Google Cloud. It includes gateway, security, analytics, developer portal, and … continue reading

Security and integration are key concerns for API management

The use of APIs has skyrocketed over the years and with organizations using so many different types of APIs on a normal basis, API management has become essential for managing the API attack surface.  Fifty-one percent of respondents said that more than half of their organizations’ development effort is spent on APIs—compared with 40% of … continue reading

Traceable AI introduces API Security Testing

The API security and observability company, Traceable AI, today announced that its API Security Testing solution in its API Security Platform is now generally available. This allows users to test any API in pre-production for vulnerabilities, accuracy, reliability, and security. According to the company, this release ensures that all APIs are aligned with the highest … continue reading

Styra introduces automated configuration file scanner

Styra, the company behind Open Policy Agent (OPA), has announced a new solution for scanning configuration files for errors. The new feature, Repo Scan, is included as part of Styra Declarative Authorization Service (DAS).  According to Styra, cloud components and platforms like AWS, GCP, and Microsoft Azure are governed and controlled by automated tooling, and … continue reading

Copado introduces new DevSecOps training module

Copado, the low-code DevOps company, today launched a new DevSecOps training module in order to make software releases faster and more secure. The module is currently available in the Copado Community. “Without DevSecOps best practices, software releases can be plagued with quality and security issues, costing more time and money post-production to correct them,” said … continue reading

Cloudera launches new data lakehouse for analytics

Cloudera announced the launch of Cloudera Data Platform (CDP) One, an all-in-one data lakehouse software for analytics and exploratory data science.  The service has built-in enterprise security and machine learning that requires no security or monitoring operations staff, helping companies move to cloud computing for analytics and data.  “Empowering everyone in your business to get … continue reading

MVP does not have to mean “Most Vulnerable Product”

Almost any company writing software today understands and glorifies the concept of Minimum Viable Product. Creating something that is just good enough for customers to successfully use it is enshrined as the most parsimonious path to profits. MVP has over time taken on additional freight as a general term connoting faster time-to-market for features or … continue reading

Checkmarx API Security released to shift API security left

Checkmarx API Security was launched to empower the partnership between the developer and AppSec teams of an organization and is delivered as part of the Checkmarx One application security platform.  Because APIs are used to access data and to call application functionality, they are easily exposed but difficult to defend which creates a large and … continue reading

New CI/CD configuration policies added to Checkov

Checkov, the open-source tool for finding infrastructure misconfigurations, has been updated with new CI/CD configuration policies. These policies can be applied across popular CI/CD frameworks like GitHub Actions, GitLab Runners, BitBucket Pipelines, CircleCI, and Argo.  Checkov has a developer-first approach to supply chain security, so it embeds these CI/CD policies directly into existing DevOps workflows … continue reading

Harness releases Security Testing Orchestration

Harness Security Testing Orchestration (STO) was launched today to help businesses deliver value quicker by increasing velocity and security in deployments. The tool automates security scanning and governance in the software delivery process. Although DevSecOps gets rid of many late-stage security concerns, it also forces developers to balance quality and speed at which to deliver … continue reading

1 8 9 10 11 12 72
DMCA.com Protection Status